Unauthorized FileIO Client Settings Exposure in Apache Polaris
CVE-2026-97395
Currently unrated
What is CVE-2026-97395?
Apache Polaris enables authenticated users to manage Iceberg table properties, including critical FileIO client settings such as s3.endpoint. In versions prior to 1.8.0, these settings can be exploited during server-side Iceberg operations—like commits and purges—leading to potential misuse of the configured storage endpoint. If the catalog storage configuration fails to override the specified endpoint, Polaris may inadvertently direct storage traffic to an endpoint designated by the table writer, potentially compromising sensitive request authentication materials. This vulnerability poses significant risks when untrusted table writers have the authority to adjust server-side storage endpoints.
Affected Version(s)
Apache Polaris 0 < 1.8.0